Threat Description

VBSWG.V@mm

Details

Summary

Subject: Check out this preteen pic!! Body: Hey here is a great preteen pic. She is 12 years old totally bald.. Attachment: Cindy12yr.vbs

Removal

Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.

Technical Details

When the attached file is executed, the worm will mail itself to the each recipient
in every address book. After mass mailing the following key is added to the registry:

HKEY_CURRENT_USER\software\Cindy\mailed

This variant also replicates using mIRC and Pirch IRC clients. It replaces the "script.ini"
from mIRC and "events.ini" from Pirch installation directories, causing that the worm
will send itself to the IRC user that joins the channel where an infected user is.

VBSWG.V also goes trough all local and network drivers from the system, and replaces
every file with either ".vbs" or ".vbe" extension with itself. It also attempts to
locate mIRC and Pirch installations from these drives.